@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects (CVE-2026-48022) | HOL Guard CVE